Security

 View Only
Expand all | Collapse all

ClearPass + 2930F Port-Authentication - weird log message

This thread has been viewed 5 times
  • 1.  ClearPass + 2930F Port-Authentication - weird log message

    Posted Feb 26, 2019 07:44 AM

    Hey guys,

     

    running Aruba ClearPass 6.7.7 + ArubaOS 16.05 on 2930F Switches, i've noticed in the switch log following events:

     

     

    I 02/21/19 08:07:23 00076 ports: ST1-CMDR: port 1/32 is now on-line
    I 02/21/19 08:07:21 00435 ports: ST1-CMDR: port 1/32 is Blocked by STP
    I 02/21/19 08:07:20 00435 ports: ST1-CMDR: port 1/32 is Blocked by AAA
    I 02/21/19 08:07:15 00900 ports: ST1-CMDR: port 1/32 timer (37) has expired
    I 02/21/19 08:07:03 00077 ports: ST1-CMDR: port 1/32 is now off-line
    I 02/21/19 08:07:03 00898 ports: ST1-CMDR: RADIUS(37) has disabled port 1/32 for
                12 seconds
    I 02/21/19 08:07:01 00076 ports: ST1-CMDR: port 1/32 is now on-line
    I 02/21/19 08:06:58 00435 ports: ST1-CMDR: port 1/32 is Blocked by STP
    I 02/21/19 08:06:58 00435 ports: ST1-CMDR: port 1/32 is Blocked by AAA
    I 02/21/19 08:04:18 00077 ports: ST1-CMDR: port 1/32 is now off-line
    I 02/21/19 08:02:42 00076 ports: ST1-CMDR: port 1/32 is now on-line
    I 02/21/19 08:02:39 00435 ports: ST1-CMDR: port 1/32 is Blocked by STP

    Configuration:

     

     

     

    interface 1/32
       untagged vlan 1
       no snmp-server enable traps link-change
       aaa port-access authenticator
       aaa port-access authenticator auth-vid 98
       aaa port-access authenticator client-limit 1
       aaa port-access mac-based
       aaa port-access mac-based auth-vid 98
       aaa port-access mac-based unauth-vid 98
       exit

     

    What feature or reason could be involved for disabling of port 1/32 for 12 seconds? Is this a CoA bouncing port for 12 seconds or is this a kind of rate limiting feature (and if, how to tweak or switching it off)?

     

    Thanks for some feedback



  • 2.  RE: ClearPass + 2930F Port-Authentication - weird log message

    Posted Feb 26, 2019 09:22 AM
    The default port bounce profile in ClearPass is 12 seconds, so that is likely it.